CISCO Talos has been tracking a cluster of espionage activity since September 2025, named UAT-11587, which by July 2026 had affected at least 16 government and policy organisations across eight Asian countries. The operation centres on a Rust-written Windows backdoor, named Antino, that runs on both 32‑bit and 64‑bit Windows.
It provides standard backdoor capabilities (shell and PowerShell access, file transfers, in‑memory shellcode loading, persistence) but communicates in a distinctive way: its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
The attackers use a five‑stage delivery chain to sidestep detection, starting with a convincing phishing email and decoy documents that mirror real public documents, including a Taiwan Ministry of Finance ruling and a real AP article, with spoofed sender details designed to bypass SPF and DMARC checks. The impersonated domain typically has a DMARC policy set to monitor rather than reject, allowing the malicious email into inboxes.
In Gmail, attackers replicated the platform’s attachment preview card to mislead recipients into clicking a link that resolves to a page controlled by the attackers.
Once activated, Antino polls its Outlook mailbox for commands every ten seconds and exchanges tasking and results via structured JSON embedded in email subjects. Stolen data is uploaded to OneDrive in a dedicated “uploads” folder, while attacker tools are pulled from a separate “downloads” folder. The operation culminates in Antino being sideloaded through a signed Microsoft diagnostic binary, with most traffic blended into ordinary HTTPS through Cloudflare Pages, Cloudflare R2, and Amazon CloudFront.
The victim list reads like a government‑focused brief: defence ministries, legislatures, foreign affairs offices, border and interior agencies, plus think tanks and civil society groups. Around 350 endpoints across eight countries have been identified, with a notable wave in India (about 57 endpoints in two days). Talos assesses with high confidence that UAT-11587 is China‑nexus. No CVEs are cited in the article.